Page 1 of 2 12 LastLast
Results 1 to 10 of 11

Thread: Is Gen:Variant.Graftor a false positive?

  1. #1
    Member
    Join Date
    Jul 2009
    Posts
    95

    Default Is Gen:Variant.Graftor a false positive?

    From the log:

    Gen:Variant.Graftor.116528: [SBI $SpybotAV] Executable (File, nothing done)
    C:\Program Files\Dropbox\Client\win32job.cp36-win32.pyd
    Category=Viruses
    ThreatLevel=5
    Weblink=http://forums.spybot.info/forumdisplay.php?54
    Properties.size=28640
    Properties.md5=7D5CF29A51E213DB5B35D87F865C1B41
    Properties.filedate=1548144844
    Properties.filedatetext=2019-01-22 08:14:04

    Category is Viruses and Rule# is SpybotAV

    but a file scan shows that it is OK.

  2. #2
    Member
    Join Date
    Jul 2009
    Posts
    95

    Default

    I add:

    Win 7 SP1 fully patched

    Spybot 2.7 with lasts updates

  3. #3
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,955

    Default

    Hello Chris Haslam,

    I will link the support team to this topic and ask.

    Best regards,

    tashi
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

  4. #4
    Member
    Join Date
    Jul 2009
    Posts
    95

    Default

    Thanks

    This item has reappeared. As you can see, DropBox is used on this computer.

    ...chris

  5. #5
    Member of Team Spybot month's Avatar
    Join Date
    Oct 2016
    Posts
    8

    Default

    Hello Chris Haslam,

    thank you for reporting this issue!
    This file belongs to the default Dropbox installation and should not be flagged as Virus by Spybot+AV. I scanned the file myself today and i could not reproduce the false positive.
    Please try updating the signatures again and hopefully it will not flag the file anymore.

  6. #6
    Member
    Join Date
    Jul 2009
    Posts
    95

    Default

    It disappeared from the Spybot report but has now re-appeared.

  7. #7
    Member
    Join Date
    Jul 2009
    Posts
    95

    Default Another false positive from Dropbox?

    The situation is the same as earlier in this thread but I now have C:\Program Files\Dropbox\Client\80.4.126\win32job.cp37-win32.pyd . Before I had C:\Program Files\Dropbox\Client\win32job.cp36-win32.pyd

    Another false positive?

    ...chris

  8. #8
    Member of Team Spybot (m/f)'s Avatar
    Join Date
    Feb 2006
    Posts
    294

    Default

    Hi, is the category Viruses and Rule# SpybotAV again? What are the file properties? I am just asking to find out where the rule at fault might be... thank you.
    (m/f)

  9. #9
    Member
    Join Date
    Jul 2009
    Posts
    95

    Default

    Yes. Category is Viruses and Rule# is SpybotAV.

    ...chris

  10. #10
    Member of Team Spybot (m/f)'s Avatar
    Join Date
    Feb 2006
    Posts
    294

    Default

    Hi again, we forwarded the issue to the corresponding team. It should be fixed soon.
    (m/f)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •